TL;DR: Manufacturers are using identity-based microsegmentation to reduce outage risk, protect legacy systems, and produce audit-ready segmentation evidence, according to Zero Networks’ customer roundup and cited IBM breach data. The governance lesson is that resilience controls must be operationally non-disruptive or they stall before they can materially reduce blast radius.
NHIMG editorial — based on content published by Zero Networks: How 3 Manufacturers Secured Production-Critical Systems with Microsegmentation
Questions worth separating out
A: Start with identity and session control, not a wholesale network redesign.
Q: Why does microsegmentation matter when attackers already have a foothold?
A: Because the attacker’s goal after entry is usually lateral movement, not staying on one system.
Q: What do security teams get wrong about microsegmentation?
A: They often treat it as a one-time network redesign instead of an iterative control that depends on current workload behaviour.
Practitioner guidance
- Map production-critical pathways first Identify the minimum set of east-west and privileged flows that production actually needs, then block everything else by default.
- Use existing enforcement points Prefer native host firewalls or other controls already present in the environment instead of introducing agents that add latency or operational uncertainty.
- Bind privileged access to network-layer MFA Apply just-in-time authentication to admin protocols and high-risk sessions so compromised credentials cannot be reused freely against legacy systems.
What's in the full article
Zero Networks' full article covers the operational detail this post intentionally leaves for the source:
- Customer-by-customer implementation timelines showing how each manufacturing environment handled rollout risk.
- Operational specifics on agentless deployment, deterministic policy automation, and host firewall orchestration.
- The exact compliance and cyber insurance evidence patterns used to validate segmentation in production.
- Quoted practitioner experience from Vermeer, Mikron, and Atlantic Constructors on implementation and outcomes.
👉 Read Zero Networks' manufacturing microsegmentation roundup →
Microsegmentation in manufacturing: are your controls keeping up?
Explore further
Microsegmentation in manufacturing is really a blast-radius problem disguised as a tooling problem. The article shows that the real obstacle is not whether segmentation works in theory, but whether it can be deployed without creating operational friction that stops adoption. For manufacturing environments, control design must assume production continuity is non-negotiable, which makes low-disruption enforcement a governance requirement rather than a convenience.
A question worth separating out:
Q: Who is accountable when segmentation is required by insurers but implementation stalls?
A: Accountability sits with the security and infrastructure leaders who own both resilience outcomes and operational change risk. If a control is too hard to deploy, it is not really a control yet. Frameworks such as NIST CSF and NIST SP 800-53 expect security outcomes to be both implemented and maintained, not merely designed.
👉 Read our full editorial: Microsegmentation in manufacturing: resilience without downtime risk